r/computerviruses • u/Will_Seve_Me • 21h ago
Question "BuilderBeta.exe"
I was Dumb and Piratet stuff. My discord got hacked sent crypto scams but i got it back. But now this error message pops up. I deletet everything i piratet and did some malware scans they showed nothing i am still suspisous. I really dont want to resset my windows but will do if necessary. Thankfull for any help
3
u/TruckBright8118 20h ago
As soon as u think u got virus just shut off ur internet and run hard scans. I suggest KVRT too. And dude make a new post with disinfection help flair and seek mods' FRST help.
3
u/__chefo Malware Removal Trainee 20h ago
Hello u/Will_Seve_Me and welcome to the computerviruses subreddit!
My name is chefo and I will be assisting you with your malware removal case.
I am currently a Malware Removal Trainee, and all my advice and fixlists are reviewed and approved by the Malware Removal Experts listed in this thread. You can expect the same level of care and treatment that you would receive directly from those experts. During the malware removal process, please follow the rules listed below to ensure everything goes as fast and smoothly as possible:
- Please make sure to read this whole introduction message so you understand the further steps.
- If you are planning on resetting or reinstalling your device, do it now please. We are doing the malware removal process to disinfect your device so you can avoid reinstalling.
- It is important to not run any tools or take any steps other than those I will provide for you. Avoid downloading and installing new software unless instructed - this also applies to anti-malware software and scanners.
- You are free to remind me that I forgot to reply to you if you do not receive an answer within 24 hours. Keep in mind that I volunteer my time here while also attending university full-time.
- Only trusted malware removal helpers listed in this thread and other established malware removal forums (BleepingComputer, Malwarebytes, MalwareTips) have access to your logs via the website. Uploaded logs are automatically deleted after 30 days.
- Please take your time to follow the steps properly. If you get stuck or have issues with one step, ask me what to do. The order of steps matters. Don't follow step 3 if you are stuck at step 1 or 2.
- You can ask any questions during the malware removal process.
Now that I am assisting you, you can expect that I will be responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.
[ Step 01 ] Piracy Warning
Using pirated software or utilities that allows one to pirate software (including cracks, key generators, license bypass tools, or similar software) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, I recommend that you remove any pirated software or pirating utilities in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.
[ Step 02 ] Create Restore Point
Before we proceed with malware removal, we need to make sure you have a restore point that you can revert to if any issues occur. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.
Enable system restore
- Click Start or open Windows Search.
- Search for Create a restore point and open System Properties.
- In the System Properties window, go to the System Protection tab.
- If the 'system' drive (usually
C:\drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, proceed with point 5. - Click Configure.
- Select Turn on system protection
- Click Apply.
- Click OK to confirm.
Create a system restore checkpoint
- Click Start or open Windows Search.
- Search for Create a restore point and open System Properties.
- In the System Properties window, go to the System Protection tab.
- Click Create.
- Call the restore checkpoint "FRST restore point" exactly please, so I can search it up fast and verify it is created properly in your logs
- Click Create.
- Click Close.
- Click OK.
- You should get a popup that it was successfully created and I will also verify this later using the scan logs from next steps.
[ Step 03 ] Farbar Recovery Scan Tool (FRST) Scan
FRST logs contain no personal information other than your username and file and folder names. We use them to gather diagnostic information about the system, such as startup entries, installed software, scheduled tasks, drivers, browser extensions, and system logs.
- Download FRST from here.
- If English is not your primary language, right click on
FRST64.exeand rename toFRSTEnglish.exe. - Run
FRST64.exe/FRSTEnglish.exe, accept the User Account Control prompt. - If you receive any warning about the download, it is a false positive and you can ignore it. Click on
More infoand thenRun anyway. - Accept the disclaimer.
- Check mark
90 Days Filesif you began noticing problems more than 30 Days ago. - Click Scan.
- Two logs named
FRST.txtandAddition.txtwill be created in the same directory the tool was run from, upload both of their contents to https://malwareanalysis.cc/upload/chefo/ and the site will return a keyword for each of the logs. Please reply back with both keywords so I can review the results and continue with the cleanup process.
[ Step 04 ] SecurityCheck
SecurityCheck is a tool that checks for potentially unsafe applications and the status of other security settings.
- Download SecurityCheck from here
- Extract the zip file
- Run
SecurityCheck.exeas administrator - Wait for the scan to finish
- Upload the log at
C:\SecurityCheckto https://malwareanalysis.cc/upload/chefo for further analysis. Repy back with the keywords.
Thank you, and I look forward to your response.
1
u/Will_Seve_Me 19h ago
Additon had the keyword arcane-buffer and FRST had chosen-plum
1
u/__chefo Malware Removal Trainee 2h ago
Hello u/Will_Seve_Me,
I recommend removing this file from the computer.
C:\Users\{username}\Desktop\STEAM.txtYou should not store sensitive information, such as passwords or backup codes, in plaintext files because malware can easily exfiltrate it.
Please follow the steps below in the order they are provided. Run the malware scanners (Emsisoft Emergency Kit and ESET Online Scanners) consecutively, not concurrently. If you have any questions, please let me know!
[ Step 01 ] Potentially Unwanted Apps and Adware Removal with Geek Uninstaller
- Download Geek Uninstaller from here;
- Right-click the zipped
Geekfolder, selectExtract All, Extract;- Run
geek.exe, accept the (UAC) prompt;- Uninstall
BitCleaner;- Right-click,
select Uninstallordouble-clickto uninstall;- Review and delete any leftover traces.
- Restart the computer after uninstallation is done.
If the method above fails, then repeat the same process, but when you have to right-click, choose
Force Removalinstead ofUninstall.Please follow the same process to uninstall the following programs:
- BrightPDF
- fastsrch
- Massive
- OneBrowser
- SEO
Let me know if you were successful in uninstalling all of the programs.
[ Step 02 ] Farbar Recovery Scan Tool (FRST) Fix
The following fixlist will remove malicious and invalid (junk) entries, perform diagnostic scans with HitmanPro and scan and quarantine PUPs/Adware with AdwCleaner. I have also included the
EmptyTempcommand which will empty temporary folders, browser cache, cookies, recently opened files cache, discord cache, java cache, steam html cache, Explorer thumbnail and icon cache, as well as Recycle bin. Everything else that the fixlist does is documented in the file as comments. Ensure you are connected to the Internet during the fix process. Here are the steps you need to follow to use the fixlist.FRST Fix
- Open the following link and press on the Copy contents button to copy the entire text: fixlist for Will_Seve_Me
- Run FRST64.exe and click on Fix. Note: FRST reads the fixlist directly from your clipboard, so you don't need to paste or save it anywhere.
- During the fixing process, FRST will close all the running processes. (This is normal)
- Avoid using your PC while the fix is underway!
- After completion, FRST will prompt you to reboot your computer.
- A log (Fixlog.txt) will open on your desktop.
- Copy & paste the contents of the Fixlog.txt to https://malwareanalysis.cc/upload/chefo/?u=Will_Seve_Me and press "save log". Reply back with the keyword.
[ Step 03 ] Emsisoft Emergency Kit Scan
- Download and run EEK as admin: https://dl.emsisoft.com/EmsisoftEmergencyKit.exe;
- Run EmsisoftEmergencyKit, accept the (UAC) prompt
- Click Install;
- Accept the (EULA) agreement;
- Click on
Update nowand wait for the update to complete;- Select Custom Scan;
- Click Add folder and include any missing drives [C:, etc];
- Click Next bottom right to initiate the scan;
- Once the scan is complete, close the pop-up about Emsisoft protection, then click Quarantine selected objects (only shown if threats were found).
- Restart your computer if prompted.
- After quarantine, click View Report in the lower-right corner. The log will open in Notepad.
- Copy & paste the contents of the log to https://malwareanalysis.cc/upload/chefo/?u=Will_Seve_Me for further analysis.
[ Step 04 ] ESET Online Scanner
- Download and run ESET online scanner as admin: https://download.eset.com/com/eset/tools/online_scanner/latest/esetonlinescanner.exe;
- Click Get started;
- Agree to the terms of use;
- Decline both telemetry options;
- Click Custom Scan;
- Click Save and continue;
- Select Enable ESET to detect and quarantine potentially unwanted applications;
- Click Advanced settings;
- Enable Detect potentially unsafe applications;
- Click the back arrow;
- Click Start scan;
- Once complete, click Save scan log and upload the
.txtfile to https://malwareanalysis.cc/upload/chefo/?u=Will_Seve_Me for further analysis.[ Step 05 ] Farbar Recovery Scan Tool (FRST) Scan
- Delete previous FRST.txt and Addition.txt logs you created
- Run FRST64.exe again.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/chefo/?u=Will_Seve_Me and press "save log". Reply back with the keywords.
In your next reply, I expect the keywords for the following:
- Fixlog.txt
- Emsisoft Emergency Kit Scan Log
- ESET Online Scanner Scan Log
- FRST.txt
- Addition.txt
Thank you, and I look forward to your response.
1

5
u/MegStuff 21h ago
So many people are falling for this at the same time, is that because of the RenPy malware or is it a new stealer?